Fictitious Network Identities Obfuscate Hacking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks are vulnerable to unauthorized access and data exfiltration due to the attractiveness of valid domain identities, which are targets for hackers seeking unrestricted access to sensitive information.

Innovation Solution

Creating fictitious network identities, also known as ambiguous or bogus identities, within the internal network using a virtual machine and security engine that employs AI algorithms to mimic valid identities, thereby obfuscating hackers and detecting unauthorized access attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If valid domain identities are exposed on the network, then authorized users can access enterprise data, but hackers can target these identities for unauthorized access and data exfiltration

Engineering Contradiction:
Improveauthorized accessVSAvoidhacker targeting
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates fictitious identities that are copies or imitations of valid domain identities. These fake identities mimic the structure, naming conventions, and appearance of real identities without possessing actual access credentials. When hackers probe the network, they encounter these copied identities instead of real ones, which obfuscates the actual valid identities and prevents unauthorized access while maintaining the appearance of legitimate identity structures.

Inventive Principle:
Principle #26Copying

2Reliability

If fictitious identities are created to obfuscate hackers, then security is enhanced, but the network identity structure becomes more complex

Engineering Contradiction:
ImprovesecurityVSAvoididentity structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The fictitious identities are designed to be homogeneous with valid identities in terms of naming conventions, structural format, and organizational patterns. By making the fake identities visually and structurally similar to real ones, the system enhances security through obfuscation without creating a fundamentally different or complex identity structure. Authorized users continue to interact with identities in the familiar, expected format, while the homogeneous appearance of fictitious identities among valid ones confuses potential attackers.

Inventive Principle:
Principle #33Homogeneity

3Measurement precision

If AI algorithms are used to create fictitious identities, then detection capability improves, but computational resources increase

Engineering Contradiction:
Improvethreat detectionVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The AI algorithms generate fictitious identities in advance and deploy them onto the network before actual threats materialize. This preliminary creation and deployment of deceptive identities allows the system to establish detection capabilities proactively. When hackers attempt to access the network, the pre-positioned fictitious identities are already in place to capture and report probing attempts, enabling early threat detection without requiring continuous heavy computational analysis during active attacks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10637864B2Creation of fictitious identities to obfuscate hacking of internal networks
Publication Date: 2020.04.28 CA TECH INC
  • US10637864B2 patent drawing
  • US10637864B2 patent drawing
  • US10637864B2 patent drawing

AI summary

Introduced here are security techniques for networks. More specifically, fictitious identities (also referred to as “bogus identities”) can be willfully created and injected into the network in order to obfuscate those who are not authorized to access the network. For example, such techniques may be used to befuddle hackers attempting to breach an internal network. The fictitious identities can be created by bypassing the operating system of computing device(s) residing within the network and deploying the fictitious identities within an operating system process responsible for implementing a security policy. Such action utilizes a limited amount of memory. The fictitious identities create a false visual of the network that is visible to any threat, regardless of where the threat is located in the network. Moreover, the fictitious identities may not infringe upon the topology of the network or affect the ability of authenticated users to continue using the network.